| Control Identifier | AT-2(1) |
| Latest Sync Date | 19/12/24 09:18:14 |
| Discussion | Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking, via spear phishing attacks, malicious web links. |
| Related Controls | CA-2, CA-7, CP-4, IR-3. |